60
Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia
d. T he wallet technology must: 1. Include a Transaction Authorization Policy (TAP) that can be directly mapped to the organization’s operational functions or business workflows, including administrative operations such as updating transaction parameters and managing whitelisted wallet addresses. 2. H ave a Policy Engine for changing user access rights that are well defined and strictly enforced.. 3. Include functionality that allows oversight and control of the control system by the authorities. 4. Include a Transaction Authorization Policy (TAP) that prevents centralized control by a single party (quorum) and is equipped with MFA. 5. Include audit logs for the system, administration, and wallet management to record all critical operations in detail. 6. Have a feature to freeze all wallet activity instantly when needed. 7. Be able to demonstrate security in the key generation and storage process (Key Management System), and include a clear and secure process for backing up cryptographic keys in the event of loss, damage, or unavailability of the primary key. 8. Include designs and procedures to enable administration in the event of bankruptcy of the Providers or Custodial System/Technology Providers, including client account reconciliation and consumer fund distribution.
Made with FlippingBook Ebook Creator